Corelight
National CERT Response to Zero-Day Cyberattack
Pages
2
Time to read
3 mins
Publication
Language
English
Pages
2
Time to read
3 mins
Publication
Language
English
This case study details a significant cyberattack on European critical energy infrastructure that occurred in May 2023, where a sophisticated threat actor executed a coordinated attack affecting 22 energy companies. The attackers exploited a critical zero-day vulnerability in firewalls protecting industrial control systems and operational technology. The event unfolded in two waves, with the initial phase showcasing stealth tactics to compromise 11 companies and a subsequent wave employing additional vulnerabilities. The coordinated defense relied on a cross-sector sensor network that provided visibility into network traffic, enabling quick identification of compromised entities. Corelight’s monitoring logs played a crucial role in detecting the attack patterns and facilitating an effective response. The proactive measures taken by the national cybersecurity team, including isolating affected organizations, successfully neutralized the attack without impacting the nation's electricity or heat supply. The incident underscored the importance of a visibility-first defense model and the necessity of high-fidelity network evidence in combating advanced cyber threats.